Cisco released security updates for CVE-2024-20399, a zero-day command injection flaw in NX-OS that was actively exploited against Cisco Nexus and Cisco MDS 9000 switches. The vulnerability stems from insufficient validation of CLI arguments and allows a local authenticated attacker with administrator privileges to execute arbitrary code as root, creating a high-impact path to full device compromise on affected network infrastructure.
Cisco and Sygnia linked the in-the-wild exploitation to the China-nexus threat group Velvet Ant, which used the flaw to deploy malware that enabled remote access, file uploads, and execution of additional malicious code on compromised switches. Defenders were urged to patch affected devices immediately and review exposed administrative access, as the attacks targeted core switching platforms that can provide durable, stealthy footholds inside enterprise environments.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco released security updates for Nexus and MDS series network switches to remediate CVE-2024-20399, a zero-day caused by insufficient validation of CLI arguments that can let an authenticated administrator execute arbitrary code as root.
Cisco and Sygnia reported that the China-nexus threat group Velvet Ant successfully exploited CVE-2024-20399, a command injection zero-day in Cisco NX-OS, to install malware that enabled remote access, file upload, and malicious code execution on affected switches.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.